VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18479 CVEsRSS

CVE-2026-65838High· 8.2
2w ago

Skipper is an HTTP router and reverse proxy for service composition

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass …

▾ Twilightzalando · skipperEPSS 0.46%via NVD
CVE-2026-15634Medium· 6.5
2w ago

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafte…

▾ SunlitIBM · WebSphere Application ServerEPSS 0.25%via NVD
CVE-2026-19816High· 7.1
2w ago

A flaw was found in PackageKit

A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transac…

▾ TwilightFedora · PackageKitEPSS 0.10%via NVD
CVE-2026-16147Medium· 6.8
2w ago

The ITE IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) mishandles multi-packet OUT transfers on non-control endpoints

The ITE IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) mishandles multi-packet OUT transfers on non-control endpoints. In work_handler_out() the active transfer buffer is obtained with udc_buf_peek() (which does not…

▾ Sunlitzephyrproject · zephyrEPSS 0.18%via NVD
CVE-2026-15924Medium· 5.9
2w ago

Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of cached client sessions that is shared by every TLS socket context

Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of cached client sessions that is shared by every TLS socket context. The functions that mutate and read it — tls_sessio…

▾ Sunlitzephyrproject · zephyrEPSS 0.31%via NVD
CVE-2026-16148Medium· 4.6
2w ago

The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv->suspended_work, suspended_handler) inside it82xx2_enable() (the driver's .enable op) in drivers/usb/udc/udc_it82xx2…

The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv->suspended_work, suspended_handler) inside it82xx2_enable() (the driver's .enable op) in drivers/usb/udc/udc_it82xx2…

▾ Sunlitzephyrproject · zephyrEPSS 0.17%via NVD
CVE-2026-18119Critical· 9.0⚖ disputed
2w ago

Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting

Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, permitting stored cross-site scripting. An editor-level user could execute script in an administra…

▾ Midnightconcretecms · concrete_cmsEPSS 0.31%via NVD
CVE-2026-18251Medium· 4.3
2w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin.

▾ SunlitIBM · iEPSS 0.14%via NVD
CVE-2026-16466High· 8.8
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.91%via NVD
CVE-2026-16335High· 8.1
2w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.42%via NVD
CVE-2026-15396Medium· 6.5
2w ago

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP request smuggling, caused by improper parsing of the HTTP transfer-encoding request header. By sending a specially crafte…

▾ SunlitIBM · WebSphere Application ServerEPSS 0.25%via NVD
CVE-2026-17156High· 7.8
2w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

▾ TwilightIBM · App Connect EnterpriseEPSS 0.14%via NVD
CVE-2026-15412Medium· 6.5
2w ago

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted We…

▾ SunlitIBM · WebSphere Application ServerEPSS 0.23%via NVD
CVE-2026-90812Medium· 4.3PoC
2w ago

A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0

A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation…

▾ Twilightcosmicstack-labs · mercury-agentEPSS 0.39%via NVD
CVE-2026-82519Medium· 4.3
2w ago

Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an u…

Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an u…

▾ Sunlitreallysimpleplugins · Really Simple SecurityEPSS 0.36%via NVD
CVE-2026-82049High· 8.4
2w ago

In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link

In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification …

▾ TwilightPython Software Foundation · CPythonEPSS 0.21%via NVD
CVE-2026-90808Medium· 6.3PoC
2w ago

A vulnerability was determined in HKUDS nanobot up to 0.2.1

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blackli…

▾ TwilightHKUDS · nanobotEPSS 0.41%via NVD
CVE-2026-89020Medium· 4.3
2w ago

MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by sup…

MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by sup…

▾ SunlitMikroTik · RouterOSEPSS 0.49%via NVD
CVE-2026-86830High· 7.2
2w ago

Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or r…

Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or r…

▾ TwilightAWS · iam-identity-center-teamEPSS 0.69%via NVD
CVE-2026-77884High· 7.1PoC
2w ago

Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network

Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.

▾ MidnightBrain Trust · Gallery - Private Photo VaultEPSS 0.25%via NVD
CVE-2026-89021Medium· 6.9
2w ago

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlink…

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlink…

▾ SunlitMikroTik · RouterOSEPSS 0.38%via NVD
CVE-2026-90809High· 7.3
2w ago

A vulnerability was identified in HKUDS nanobot up to 0.2.1

A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argu…

▾ TwilightHKUDS · nanobotEPSS 0.56%via NVD
CVE-2026-89023High· 8.6
2w ago

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can ret…

▾ TwilightThemeAtelier · Domain For SaleEPSS 0.39%via NVD
CVE-2026-19543Medium· 6.2
2w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can m…

▾ SunlitIBM · Common LicensingEPSS 0.12%via NVD
CVE-2026-18515Medium· 4.3
2w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the…

▾ SunlitIBM · iEPSS 0.28%via NVD
CVE-2026-90810Medium· 6.3PoC
2w ago

A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13

A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell…

▾ Twilightcosmicstack-labs · mercury-agentEPSS 0.37%via NVD
CVE-2026-82035High· 7.1
2w ago

PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a document-controlled BaseFont name …

PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a document-controlled BaseFont name …

▾ TwilightPyMuPDF · PyMuPDFEPSS 0.32%via NVD
CVE-2026-90811Low· 3.3PoC
2w ago

A weakness has been identified in cosmicstack-labs mercury-agent up to 1.2.0

A weakness has been identified in cosmicstack-labs mercury-agent up to 1.2.0. This affects the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Permission Manif…

▾ Twilightcosmicstack-labs · mercury-agentEPSS 0.15%via NVD
CVE-2026-18151Medium· 4.2
2w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process.

▾ SunlitIBM · iEPSS 0.14%via NVD
CVE-2026-15893Medium· 6.5
2w ago

net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max…

net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max…

▾ Sunlitzephyrproject · zephyrEPSS 0.20%via NVD
CVEs tagged “cve.org” — page 324 · VulnSea